Persistent 'Effluence' Backdoor Exploited in Widespread Atlassian Confluence Attacks

1 min read
Source: The Hacker News
Persistent 'Effluence' Backdoor Exploited in Widespread Atlassian Confluence Attacks
Photo: The Hacker News
TL;DR Summary

A stealthy backdoor named Effluence has been discovered by cybersecurity researchers, persisting despite patching Atlassian Confluence servers. The backdoor allows for lateral movement to other network resources and data exfiltration from Confluence, and can be accessed remotely without authentication. The attack chain involves exploiting critical vulnerabilities in Atlassian Confluence, including CVE-2023-22515 and CVE-2023-22518, which allow for unauthorized administrator account creation and complete loss of confidentiality, integrity, and availability. The attacker gains initial access through CVE-2023-22515 and embeds a web shell that grants persistent remote access to every web page on the server. The web shell's loader component acts as a normal Confluence plugin, while the payload component executes malicious actions. The backdoor is potentially applicable to other Atlassian products as well.

Share this article

Reading Insights

Total Reads

0

Unique Readers

20

Time Saved

1 min

vs 2 min read

Condensed

68%

376121 words

Want the full story? Read the original article

Read on The Hacker News